Dropped Files | ZeroBOX
Name 92fddff74df2e1e3_vsockver.dll
Submit file
Filepath C:\Users\test22\bortrationaliserings\Saban\Sekundaere\Banktilsynet\vsockver.dll
Size 2.0KB
Processes 2544 (Rendestene.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 dd45c98f8b799392c25b7f40a58cdf8b
SHA1 47a016a0d7005f69f85adf9851663ddb8d357d08
SHA256 92fddff74df2e1e344f24921e2f4312f5b84cc27c2122e12869af3af1a235739
CRC32 9F64748C
ssdeep 24:e9GSFlf8EzAusypMS9N5hVbG7+3b0PNjQ:KFeEznhpMqdbGgIE
Yara
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 724c2383f7b43dd6_behandlingsmaal.oxy
Submit file
Filepath C:\Users\test22\bortrationaliserings\Behandlingsmaal.Oxy
Size 217.9KB
Processes 2544 (Rendestene.exe)
Type data
MD5 8d1aa639a4584ff8b0e4c6ba24c615bc
SHA1 56a0f85360fe4218c3d559b7307599c559af6074
SHA256 724c2383f7b43dd6f80d298f25e86fc3f97f3a53ac86c065efe270a6923c74a2
CRC32 B33B69F6
ssdeep 6144:khPTnE+o107TunLL2UdE2Ppofdu5CNgPI/f0M:so2TSCUdLPpoMQqPIX0M
Yara None matched
VirusTotal Search for analysis
Name c2f405d7402f815d_system.dll
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\nsbEFEE.tmp\System.dll
Size 11.5KB
Processes 2544 (Rendestene.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 9625d5b1754bc4ff29281d415d27a0fd
SHA1 80e85afc5cccd4c0a3775edbb90595a1a59f5ce0
SHA256 c2f405d7402f815d0c3fadd9a50f0bbbb1bab9aa38fe347823478a2587299448
CRC32 9463F62F
ssdeep 192:eX24sihno00Wfl97nH6BenXwWobpWBTtvShJ5omi7dJWjOlqSlS:D8QIl972eXqlWBFSt273YOlqz
Yara
  • IsDLL - (no description)
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
VirusTotal Search for analysis
Name 74e659e149c31ae5_osmazomatous.tro
Submit file
Filepath C:\Users\test22\bortrationaliserings\Nosepinch\Fjert\Mors\Osmazomatous.tro
Size 19.7KB
Processes 2544 (Rendestene.exe)
Type ASCII text, with very long lines, with no line terminators
MD5 771f04a848415ffc18913c3f73c11c0d
SHA1 4675b146880628432142668952293a2c6fcfbe99
SHA256 74e659e149c31ae5c75325afddd923132201216a14f7785c60414fea10945bd2
CRC32 7D4FBB93
ssdeep 384:o3h65zRdITCkBnXEEkC5LyBYznWKJczd6eQEV1:wh65zRdITC2nXEEkC5LyBYznWVzd6hE7
Yara
  • Suspicious_Obfuscation_Script_2 - Suspicious obfuscation script (e.g. executable files)
VirusTotal Search for analysis
Name 7782e1c2d04d40ba_battery-level-0-charging-symbolic.svg
Submit file
Filepath C:\Users\test22\bortrationaliserings\Duikerbok\Wetproof\Causticized\Lysbadene\battery-level-0-charging-symbolic.svg
Size 1.6KB
Processes 2544 (Rendestene.exe)
Type SVG Scalable Vector Graphics image
MD5 0088da6debe653132b810df26a9ae491
SHA1 1cd98ee01ebb448aca9e13cd5d4ecb5cee0eacda
SHA256 7782e1c2d04d40ba9228b2e9b5a3efca2d8e4e153e53238b0a7e4b1f74289cfa
CRC32 34F778B8
ssdeep 24:t4CBGD0l+2jwcC4tyKbRAecFhBrNx0/53mnFb5DqyKbRAecFhBrNx0/JGEemZK:gDqFCeNtAecFZwxgl+NtAecFZwJGJmM
Yara None matched
VirusTotal Search for analysis
Name e3b0c44298fc1c14_nsgEF22.tmp
Empty file or file not found
Filepath C:\Users\test22\AppData\Local\Temp\nsgEF22.tmp
Size 0.0B
Type empty
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
CRC32 00000000
ssdeep 3::
Yara None matched
VirusTotal Search for analysis